ZeroHour

CVE-2012-5076

KEVmass

Java Sandbox Bypass in Oracle Java SE

CISA: Oracle Java SE Sandbox Bypass Vulnerability

CVSS
EPSS
91%p100
Published
KEV added
AI analysis

CVE-2012-5076 is a Java sandbox bypass caused by the default Java security properties configuration, which failed to restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. The flaw is triggered when an untrusted Java application or applet is run and abuses access to these packages to escape the Java sandbox. An attacker who successfully exploits it gains the ability to execute code with elevated privileges beyond the sandbox restrictions that are supposed to contain untrusted Java code. Any environment running affected Oracle Java SE and executing untrusted Java code — most notably browsers with the Java plugin loading applets — is exposed, and CISA lists Oracle Java SE as the affected product. CISA added this vulnerability to the KEV catalog on 2022-03-28, indicating known exploitation in the wild; no public proof-of-concept is known, and ransomware use is unknown.

What to do: Apply Oracle's updates per vendor instructions, as required by the CISA KEV listing — upgrade all Java SE deployments to the current patched release and verify no systems remain on unpatched builds. As mitigation, disable the Java browser plugin or block untrusted applets and applications where full patching is not yet possible, and monitor for exploitation activity consistent with exploit kit delivery.

Affected
Oracle Java SE
Estimated exposure
masshundreds of millions of installations (Java runtime is ubiquitous; Oracle has historically cited over a billion Java-enabled devices) — Java SE is one of the most widely deployed runtimes, with Oracle citing billions of Java-enabled devices and desktops, and untrusted applet/application execution was common, so the plausible affected population is in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

CISA Known Exploited Vulnerability
Affected
Oracle Java SE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
Java SE

In the news